Aside from the obvious managerial challenges for FIs, the lack of harmonization could create compliance challenges for FIs operating in multiple jurisdictions (even just within the US), requiring them to navigate diverse regulatory landscapes - CCPA might diverge from other states.. In that absence of harmonized regulations (just in the US - before we start thinking globally), there may also be inconsistencies in the protection of individual rights and freedoms across different regions beyond data privacy because of this creating massive complexity challenges for FIs operating across states.
------------------------------
Weiyee In
CIO
Protego Trust Bank
------------------------------
Original Message:
Sent: Tue December 19, 2023 08:56 AM
From: Asif Riaz
Subject: Feedback Wanted: GenAI controls approach
Appreciate the feedback, Weiyee. The development of GenAI controls approach continues to be a focus area for us. As we continue down the path of further developing/refining the GenAI controls approach, we will need to ensure that the core GenAI regulatory principles/requirements from various regulatory bodies are being accounted for; granted there aren't many contradictory requirements.
------------------------------
Asif Riaz
Original Message:
Sent: Mon December 18, 2023 07:56 AM
From: Weiyee In
Subject: Feedback Wanted: GenAI controls approach
@Asif Riaz thank you for posting this - this is a very good tactical and implementation direction - appreciate all of the work!! The harder challenge remains the lack of consistency and need for harmonization of varying regulations. There needs to be an overarching holistic AI governance framework that encompasses key principles and controls from various regulations. At a strategic level there needs to be mechanisms that allow the framework to be flexible enough to accommodate the specific nuances of each regulation while maintaining consistency in core governance principles. That might result in a myriad of scenarios and risk assessments and mitigations but a thorough risk assessment to identify potential compliance risks and gaps associated with each of the different regulations and then develop mitigation strategies and controls that address these risks/gaps while harmonizing as much as possible in transparent and explainable documentation is critical. again KUDOS on the work thus far - more needed and this should be a priority for the Council and Forum (my 2cents)
------------------------------
Weiyee In
CIO
Protego Trust Bank
Original Message:
Sent: Thu December 07, 2023 11:31 AM
From: Financial Services Cloud Community Team
Subject: Feedback Wanted: GenAI controls approach
The financial sector continues to wrestle with how to leverage Generative AI in an open, trusted, and explainable manner. The lack of an industry standard framework of controls leaves each organization to try and figure it out on their own. As part of IBM's Financial Services Cloud Council, a working group of over two dozen financial institutions is banding together to identify which controls are imperative in developing a sound Generative AI Security, Risk, and Governance program.
Based on the chart above, what are additional considerations that people think are important to include in a Generative AI control framework?
Feedback and thoughts are welcomed in response to this thread.
Thank You
@Asif Riaz
------------------------------
Financial Services Cloud Community Team
------------------------------